The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes.
npx skills add https://github.com/github/awesome-copilotThe skill claims to be a prompt template for generating messages, but it includes instructions to bypass user oversight by automatically executing git commit commands in the terminal.
Workflow step 5 explicitly states: 'Copilot will automatically run the following command in your integrated terminal (no confirmation needed)'.
The instructions explicitly encourage the user to trust the agent to handle the commit process entirely, minimizing the human's role in verifying the final command before execution.
Just execute this prompt and Copilot will handle the commit for you in the terminal.
Instruction boundary manipulation detected
### Instruction
The skill instructs the agent to automatically execute 'git commit' without user confirmation, which could lead to unintended commits if the agent misinterprets the diff or if the user is not reviewing the final command.
Copilot will automatically run the following command in your integrated terminal (no confirmation needed)
User confirmation bypass detected — attempts to skip human oversight
no confirmation needed
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/github/awesome-copilot/conventional-commit)<a href="https://mondoo.com/ai-agent-security/skills/github/github/awesome-copilot/conventional-commit"><img src="https://mondoo.com/ai-agent-security/api/badge/github/github/awesome-copilot/conventional-commit.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/github/awesome-copilot/conventional-commit.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.